CVE-2023-4803
Summary
| CVE | CVE-2023-4803 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-13 16:15:00 UTC |
| Updated | 2023-10-13 22:15:00 UTC |
| Description | A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript within another web console administrator's browser. All versions prior to 7.14.3.69 are affected. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Proofpoint | Insider Threat Management | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page Not Found | Proofpoint US | MISC | www.proofpoint.com | |
| ITM Server Multiple Cross-site Scripting Vulnerabilities | Proofpoint US | MISC | www.proofpoint.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.